PT-2020-20363 · Google · Google Closure Library
David Schütz
+1
·
Published
2020-03-26
·
Updated
2024-11-27
·
CVE-2020-8910
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Google Closure Library versions up to and including v20200224
Description
A URL parsing issue in goog.uri of the Google Closure Library allows an attacker to send malicious URLs to be parsed by the library and return the wrong authority.
Recommendations
For Google Closure Library versions up to and including v20200224, update your library to version v20200315.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Google Closure Library